CVE-2006-6133
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 51%
from disclosure to weapon0 days
Published on NVDNov 28
1st PoCNov 23
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/29171⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-052http://secunia.com/advisories/23091http://secunia.com/advisories/26754http://securitytracker.com/id?1017279https://exchange.xforce.ibmcloud.com/vulnerabilities/30532https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2055http://www.lssec.com/advisories/LS-20061102.pdfhttp://www.securityfocus.com/archive/1/452464/100/0/threadedhttp://www.securityfocus.com/bid/21261http://www.us-cert.gov/cas/techalerts/TA07-254A.htmlhttp://www.vupen.com/english/advisories/2006/4691http://www.vupen.com/english/advisories/2007/3114